Skip to main content
TR

DIGITAL FORENSICS

Course
ITSE306 - DIGITAL FORENSICS
Department
Information Technology Security - English - Undergraduate
Course Type
Course
Status
Required
Language
Turkish
Credit
3
ECTS
6
T+P+L
3 + 0 + 0
Course Coordinator(s)
-
Prerequisite
-
Keywords

Course Description

The main objective of this course is to teach students different techniques and procedures that enables them to perform digital investigation. This course focuses mainly on the analysis of physical storage media and volume analysis. It covers the major phases of digital investigation such as preservation, analysis and acquisition of artifacts that reside in hard disks and random access memory. At the completion of the course, student will be able to create a digital image of physical storage device, they will be able to recovered deleted digital information and they will be able to use common digital forensics tools. Students will also be able to analyze various cases to determine digital actions of a user and perform digital analysis of varieties of files

DIGITAL FORENSICS

Evaluation Tools (Active Term)

No evaluation items have been defined.

Course outcomes

No course outcomes have been defined yet.

Course Syllabus

Week Topic
Week 1 Introduction to Digital Forensics
Week 2 Fundamentals of Computer Forensics
Week 3 Types of Cybercrimes
Week 4 Digital Evidence and Rules of Evidence
Week 5 Forensic Readiness, Business Continuity, and Laboratory Planning
Week 6 Computer Forensics Investigation Process
Week 7 Crime Scene and Digital Evidence Processing
Week 8 Data Acquisition, Duplication, and Hashing
Week 9 Hard Disks, SSDs, and File Systems
Week 10 Midterm(s)
Week 11 Windows Registry, Boot Process, and Disk Encryption
Week 12 Autopsy and The Sleuth Kit Applications
Week 13 Digital Forensics Tools and Tool Validation
Week 14 Graphics Files, Image Recovery, and Steganalysis
Week 15 Virtual Machine, Network, E-mail, and Social Media Forensics

Reference Books & Course Materials

No reference books have been listed.

Learning Outcomes

  1. L01 Explain the fundamental concepts, scope, and importance of digital forensics in cybersecurity investigations. SOLO 4
  2. L02 Describe the characteristics of cybercrimes, digital evidence, and the rules of evidence used in forensic investigations. SOLO 3
  3. L03 Apply the main stages of the computer forensics investigation process, including crime scene handling, evidence processing, and documentation. SOLO 4
  4. L04 Perform data acquisition, duplication, and hashing procedures to preserve the integrity of digital evidence. SOLO 4
  5. L05 Analyze storage media, file systems, Windows registry, boot processes, and disk encryption artifacts during forensic examinations. SOLO 4
  6. L06 Apply common digital forensic tools and validation methods to recover, examine, and interpret digital artifacts. SOLO 4
  7. L07 Examine graphics files, deleted images, steganalysis indicators, and artifacts related to virtual machine, network, e-mail, and social media forensics. SOLO 3
  8. L08 Evaluate forensic practices in relation to legal, ethical, and professional responsibilities, including evidence handling, forensic readiness, and business continuity. SOLO 5

Program Outcomes

  1. P01 Apply data science principles and techniques to challenges in real life situations, and effectively communicate their solutions.
  2. P02 Identify and implement data analysis methodologies based on theoretical ideas, ethical code, and in-depth knowledge of the underlying data.
  3. P03 Analyze the guiding concepts and assessment procedures for information analysis in real-life applications.
  4. P04 Design and apply relevant data analysis models to find obscure solutions to business-related problems.
  5. P05 Utilize modern computing techniques to handle real-world problems characterized by massive amounts of data, such as parallel and distributed computing and machine learning.
  6. P06 Configure and administer the software tools required to efficiently produce usable information from any size of structured and unstructured datasets.
  7. P07 Administer or manage data science tools and techniques to organize and complete projects aimed at gaining useful insight from complex data.
  8. P08 Think critically and imaginatively, conceiving real-world issues from several angles, and work well in a variety of teams to solve issues cooperatively.
  9. P09 Be able to effectively integrate data‐based solutions into the user environment and help non-technical professionals in exploring, visualizing, and using these solutions
  10. P10 Understand their obligations under professional and ethical standards in relation to matters like data ownership and citation, data security and sensitivity and the privacy implications of data analysis.

Po-Lo Matrix

LO P01 P02 P03 P04 P05 P06 P07 P08 P09 P10 Average
L01 - - - - - - - - - - -
L02 - - - - - - - - - - -
L03 - - - - - - - - - - -
L04 - - - - - - - - - - -
L05 - - - - - - - - - - -
L06 - - - - - - - - - - -
L07 - - - - - - - - - - -
L08 - - - - - - - - - - -